← back
CVE-2024-2961highobserved exploitationCWE-787

CVE-2024-2961

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.3epss 88%
from disclosure to weapon40 days
Published on NVDApr 17
1st PoC+40d
metasploit+100d
VulnCheck+152d
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesVulnCheck
11 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products (10 components)
Red Hat Enterprise Linux 6 · Red Hat OpenShift Container Platform 4
workaround: This issue can be mitigated by removing the ISO-2022-CN-EXT from glibc-gconv-extra's modules configuration. This can be done by: 1) Verify if the module is loaded by running: ~~~ $ iconv -l | grep -E 'CN-?EXT' ISO-2022-CN-EXT// ISO2022CNEXT// ~~~…
Fixed
41 products (8,334 components)
Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux BaseOS EUS (v.8.8) · Red Hat Enterprise Linux BaseOS EUS (v.8.6) · Red Hat Enterprise Linux BaseOS (v. 9) · Red Hat Enterprise Linux BaseOS EUS (v.9.0) · and others 36
Not affected
8 products (2,994 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 4.14 · Red Hat OpenShift Container Platform 4.16 · Red Hat OpenShift Container Platform 4.13 · Red Hat OpenShift Container Platform 4.15 · Red Hat OpenShift Container Platform 4.12 · and others 3
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.